Releases: data-goblin/omgato
Release list
Omgato 0.1.7
This file was written by an agent.
- Replace the bar emblem with a larger, clearer play glyph.
- Preserve light names, ordering, and history when network addresses change.
- Automatically rediscover unreachable Key Lights and retry failed control commands.
- Use MAC addresses for light rename and ordering CLI options.
Omgato 0.1.6
Omgato 0.1.6 closes the remaining Key Light cache-path issue identified during marketplace review.
Security
- Opens the mutable
lights.tomlcache once withO_NOFOLLOW,O_NONBLOCK, andO_CLOEXEC. - Validates that same descriptor as a regular file owned by the current user before reading it.
- Reads only from the validated descriptor through the existing 64 KiB cap, eliminating the path-reopen race and preventing FIFO blocking.
Validation
- Adds regression coverage for symlinked caches, FIFO caches, foreign ownership, and valid regular cache files.
- Passes the complete workspace test suite, Clippy with warnings denied, QML linting, and
omarchy plugin validate.
Omgato 0.1.5
Omgato 0.1.5 is a security-hardening release for the Key Light integration.
Security
- Caps raw mDNS discovery output at 256 KiB, ARP output at 64 KiB, ARP entries at 256, and discovered or cached lights at 32.
- Validates and bounds retained host, name, IP, port, and MAC fields before storing device state.
- Caps Key Light HTTP JSON responses at 16 KiB and rejects responses with an unexpected number of light states.
- Replaces one OS thread per discovered light with a fixed worker pool of at most four threads while preserving result order.
Validation
- Adds regression coverage for oversized discovery and HTTP responses, excessive devices, invalid fields, bounded cache state, and worker concurrency.
- Passes the complete workspace test suite, Clippy with warnings denied, QML linting, and
omarchy plugin validate.
Thanks to the Omarchy plugin marketplace maintainers for the detailed follow-up security review.
Omgato 0.1.4
Omgato 0.1.4 is a patch release fixing a regression introduced in 0.1.3.
Fixed
- Restored every
camlink-ctlcommand on machines upgraded from an earlier version. The blockers directory created under the previous umask was refused as group-readable rather than narrowed, sostatus,show,hideandreplaceall exited with an error. A directory this user already owns is now narrowed to0700and re-checked; anything not owned by the user is still refused.
Changed
- Removed comments outside CLI help text. The
--helpoutput of all four tools is byte-identical to 0.1.3.
Anyone on 0.1.3 should update.
Omgato 0.1.3
Omgato 0.1.3 completes the local-privilege hardening of runtime state, atomic outputs, process handling, and shared output directories.
Security
- Anchored private runtime and fallback directories below trusted ancestors, rejecting symlinks, foreign ownership, and unsafe writable parents.
- Hardened legacy migrations so they move only real files and secured directories without a symlink-following copy fallback.
- Published logs, state, and configuration updates from exclusively created per-process inodes.
- Reserved recording, processed-video, and Stream Deck export paths before external tools open them.
- Removed the shared
/tmpfallback for the Hyprland compositor socket. - Bound camera holders and overlay signals to stable process identities, including start-time rescans and pidfds.
Fixed
- Initialised secured state before acquiring resources and returned normally from panel commands so cleanup guards run.
- Rejected Stream Deck page names that could escape a selected export root.
All four Rust tools and the plugin manifest are versioned 0.1.3.
Full change set: PR #4
Omgato 0.1.1
Omgato 0.1.1 is a reliability release focused on camera overlay lifecycle safety, display changes, and complete migration from the plugin's former name.
Fixed
- Serialised camera overlay commands so show, hide, avoidance and release cannot race each other.
- Kept overlays visible after display changes by resolving and clamping placement against the current monitor layout.
- Recovered orphaned camera processes and expired claims left behind by crashed owners without disturbing live owners.
- Borrowed camera devices safely from every matching systemd user unit, including safe failure handling when a process cannot be terminated.
- Migrated configuration, state, runtime data, links and shortcuts left under the plugin's former name.
- Restored Key Lights by network identity and surfaced partial restore failures.
- Kept panel claims aligned with the panel's actual screen and released them when camera controls are disabled or the panel is destroyed.
- Centred the Omgato mark reliably within its panel item.
All four Rust tools and the plugin manifest are versioned 0.1.1.
Full change set: PR #3